enTrans: a demonstration of flexible consistency maintenance in provisioning systems
Shyamsunder Gopale, Shridhar B. Shukla, R. Kul, Rajnish Kumar Jha · 2005
One of the greatest administrative and security challenges within every IT and HR organization is provisioning — providing users with appropriate access to enterprise information and technology resources. This is especially true in today's volatile business environment, where employee turnover, cost cutting and consolidation are all constant occurrences. Traditionally, the provisioning process has been paper-based, processintensive, bureaucratic and hard to track. Today, it is even harder to manage because of the growing variety of systems within an organization and the high cost of managing user identities and permissions across organizations. Automated provisioning streamlines this process, giving new employees, partners and clients faster access to the resources they need to interact productively with your organization. A provisioning system also facilitates de-provisioning — the rapid removal of access rights when a user leaves the company — which is especially critical to enterprise security. Persistent’s enQuire Virtual Directory Server [3] is a product which provides a LDAP v3 standards based solution for automatic provisioning of user identities. It provides a unified view of a user’s network identity, which is typically fragmented over different systems in an organization. It has the capabilities to merge the different fragments of a user’s identity and provide the administrator of the provisioning system with a single consolidated identity for a user. To maintain the integrity and security constraints associated with such provisioning operations enQuire needs to provide transaction capabilities over the unified identity of a user. The network identity of a user is created, by linking together various fragments based on some common information, which is shared across the different identity fragments. So, whenever parts of this shared identity are updated it is imperative that consistency is maintained across the different systems from where the unified entry is created. This brings about the need of transactional support in performing these kinds of identity operations. enQuire internally uses LDAP to perform its identity management operations. Unfortunately, LDAP supports only atomic updates at the individual entry level and, today, the applications are forced to take ad-hoc measures to maintain consistency across multiple data repositories. A systematically developed transaction support for consistent updates across multiple data repositories is therefore imperative. The provisioning applications increasingly involve long duration activities and hence the traditional OLTP transaction support is inadequate. Thus the transaction support should support advanced transaction models, as well; or, at least, should have primitives to facilitate implementation of the advanced model with little effort. The users of the system expect the transaction support for LDAP to be as simple to use, as are LDAP primitives. With these compelling motivations, we have developed enTrans, a highly flexible and customizable transaction support facility that works with the enQuire Virtual Directory server. The enTrans framework provides advanced transaction support for provisioning applications and a mechanism to define and enforce application specific integrity constraints. enTrans uses Predefined Trigger Access Protocol (PTAP) [1] for providing the necessary transactional support.